STARM · NW-08 · NETWORK

Ground Station Breach

Back to the STARM matrix

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Hacking terrestrial IT to control satellites.

Severity in the dataset9/10

Not the paper’s H/M/L.

Target
Network Access
Layer in the inventory
Application / Network Layer
Mitigation
Network isolation (Air-gapping) and MFA.
How the inventory says to fix it
Rule-based: Air-gapping core networks. AI: UBA to detect anomalous admin logins.
Quick fix
Change gateway
ML approaches named
User & Entity Behavior Analytics (UEBA), Random Forest, XGBoost, Autoencoders, Transformer-based log analysis
Methodology
Abnormal operator commands, unusual login patterns, deviations in operational workflow, privilege misuse
Handler role
SOC Analyst
Stage
Operation
Standard named
ISO/IEC 27001
Status in the inventory
Avoided

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Related in the matrix

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Connection recorded in the inventory

Insider Threat